惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 【当耐特】
Engineering at Meta
Engineering at Meta
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
小众软件
小众软件
有赞技术团队
有赞技术团队
MyScale Blog
MyScale Blog
A
About on SuperTechFans
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Jina AI
Jina AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
云风的 BLOG
云风的 BLOG
Vercel News
Vercel News
博客园_首页
T
Troy Hunt's Blog
I
InfoQ
M
MIT News - Artificial intelligence
aimingoo的专栏
aimingoo的专栏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Proofpoint News Feed
博客园 - 司徒正美
Cloudbric
Cloudbric
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Forbes - Security
Forbes - Security
D
Docker
Attack and Defense Labs
Attack and Defense Labs
Google DeepMind News
Google DeepMind News
N
News and Events Feed by Topic
博客园 - 聂微东
S
Security Affairs
Security Archives - TechRepublic
Security Archives - TechRepublic
WordPress大学
WordPress大学
N
News and Events Feed by Topic
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Heimdal Security Blog
大猫的无限游戏
大猫的无限游戏
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Threat Research - Cisco Blogs
Blog — PlanetScale
Blog — PlanetScale
A
Arctic Wolf
J
Java Code Geeks
F
Full Disclosure
L
Lohrmann on Cybersecurity
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Project Zero
Project Zero
GbyAI
GbyAI
B
Blog
爱范儿
爱范儿

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
Foreign Entities Such As China Are Siphoning American AI Models At Our Steep Loss And Their Huge Gain
Lance Eliot · 2026-05-01 · via Forbes - Innovation
Diverse Group of Professionals Meeting in Modern Office: Brainstorming IT Programmers Use Computer Together, Talk Strategy, Discuss Planning. Software Engineers Develop Inspirational App Program

Foreign entities are using AI distillation to illegally siphon from American-made advanced AI.

getty

In today’s column, I examine the underhanded and insidious efforts by foreign entities to siphon off American-made generative AI and large language models (LLMs), doing so to craft their own AI variations at a fraction of the cost and to exploit the hard-earned progress made in AI by the United States.

It is outrageous, illegal, and being undertaken surreptitiously. The United States is urgently taking notice on behalf of American AI makers and performing rapid action to detect, curtail, and seek to prevent these shameful and unlawful intrusions.

Let’s talk about it.

This analysis of AI breakthroughs is part of my ongoing Forbes column coverage on the latest in AI, including identifying and explaining various impactful AI complexities (see the link here).

The AI Technique Of Distillation

I will start by covering crucial foundational considerations.

Suppose an AI maker wants to use one of their existing full-sized AI models to enhance a smaller and less capable one of their AI models. This can be readily performed via a technique known as distillation. The typical use of distillation involves an AI maker deciding to create or enhance an SLM (small language model). They pour some of the contents of the LLM into the SLM, aiming to further fill in or pump up what the SLM can do (see my detailed explanation on how AI distillation works, at the link here).

You can think of AI distillation as a teacher-student type of arrangement. The LLM acts as the teacher. The SLM is the student. The larger-sized LLM shares aspects with the SLM to bolster the capabilities of the smaller AI. This is a relatively routine practice and is commonly undertaken. AI makers do this frequently, and so do AI practitioners and hobbyists. If done appropriately and legally, it is perfectly aboveboard.

The twist is that distillation can be utilized in a legal way but can also be performed illegally.

The illegal approach involves surreptitious distilling from someone else’s LLM and essentially stealing their intellectual property (IP). Why would this be done? Because you can take a relatively slim or hollow SLM and pump it up to become much more full-bodied at a super low price. The SLM emerges as a robust LLM overnight. Rather than having to pay and get suitable approval, the underhanded path rips off the hard work and vast invested efforts of whoever made and owns the teaching LLM.

Being Sneaky And Stay Below The Radar

You might be thinking that detecting when an illegal distillation is taking place ought to be easy-peasy. All you seemingly need to do is monitor when the teaching LLM is actively giving up tons of its content. It would be akin to a water pipe that someone turned on widely or slyly tapped into, and the water is gushing out. If the contents of the teaching LLM are gushing out, voila, you’ve got an unauthorized distillation happening.

The thieves are wise to such adversarial detection. They know that if they simply pumped out content at a high rate of distillation, doing so would be caught and summarily cut off. It is a much too obvious form of a cyberhack. Though an individual who isn’t in the know might try this blatant means, a large entity or actor would be too astute to fall into that crude method.

A sophisticated cyberhacking would employ proxy swarms. You might liken this to using thousands upon thousands of small drones. Drones are relatively small, cheap, and yet are extraordinarily powerful when used in a massive way. We’ve all seen how lots of drones working in unison can readily threaten a large warship at sea or an expensive large-sized warplane.

Spinning Up Thousands Or Millions Of Accounts

In the case of AI distillation thievery, here’s how a foreign entity might proceed. Keep in mind that a foreign entity could be a country or some entity that has sizable resources to devote toward cyberhacking.

The entity creates thousands or perhaps millions of fake accounts in the generative AI model that is being targeted. This isn’t being done singularly by human hand. Instead, an automated script running on a computer server will create these accounts (they become AI bot-controlled accounts). Furthermore, servers across the globe are tapped into so that the accounts appear to be geographically dispersed. It isn’t obvious where the accounts originate from.

If you are wondering why an AI maker wouldn’t instantly get suspicious about perhaps millions of new accounts, the gist is that many of the major LLMs already have hundreds of millions of accounts, and new accounts by actual people are being created at an amazing pace. OpenAI has stated that ChatGPT and GPT-5 have somewhere around 900 million weekly active users. The stats suggest that with ChatGPT, GPT-5, Google Gemini, Anthropic Claude, xAI Grok, Microsoft CoPilot, and additional mainstay LLMs, the number of worldwide AI users in total is perhaps 1.5 billion or more.

Thus, creating thousands or even millions of new accounts by a cyberhacker is not going to raise alarm bells, especially by dispersing the geographic origins of the accounts. It will look as though more people from around the world are opting to make use of modern-era generative AI. No-harm, no-foul.

Don’t Need To Break Glass

Does distillation break or crack the AI and, therefore, ought to be detectable?

Nope, it is the mere act of submitting prompts and obtaining responses. The idea is straightforward for doing the distilling. Suppose you wanted to find out what AI can tell you about Einstein’s most famous equation. You could merely ask a question and get a response. Then, based on the response, you ask another question. Keep doing this until it seems that you’ve extracted as much as feasible from the AI about e=mc squared.

Collect together all those prompts and responses. Keep them recorded as pairs. Those prompt-response pairs are then fed into the AI that you are trying to train in Einstein’s theory of relativity. By pumping in perhaps thousands or millions of such pairs, the other “student” AI patterns on the prompts and responses, ultimately becoming boosted on the topic of Einstein’s theory.

No need to do anything tricky or out of the ordinary. Just submit prompts, collect responses, and do so until it seems that enough has been distilled to move on to some other topic. Distillation has the appearance of an everyday user who is interacting with the AI on a normal basis. You would be hard-pressed to discern that it was a bot that was essentially stealing from the AI.

Is It Stealing If Only Dipping In

A frequent question comes up when I give talks about AI and distillation, namely that AI distillation doesn’t especially seem to be a crime per se. Normal users are allowed to enter prompts and get responses from LLMs. The cyberhacker is doing the same.

What’s the beef?

If you were to inspect the online licensing agreements of the AI makers, you’ll see a clause that says you cannot use the prompt-response pairs for distillation. The AI makers don’t want you to use their AI for distillation, and adamantly stipulate that you aren’t to do so. It is a flat no. You are welcome to use the prompt-response pairs for all sorts of other purposes, but not for distillation.

Another angle about whether this is legal or illegal has to do with the fact that when you get the AI to give you responses, you aren’t actually removing anything from the AI. The AI is merely sharing with you a response. It displays contents. The actual contents of the AI are still intact. In that sense, it perhaps seems odd to claim that you are “stealing” from the AI.

We customarily think of stealing as removing an item. When someone steals a camera that’s in the front seat of your car, they take the camera away from the car, and they rob you of the possession of the camera. The AI giving you a response to a prompt is not going to somehow remove content from the AI.

The more appropriate way to think of this is when someone makes a bootleg copy of a movie, the original movie is still intact, but the bootlegger has nonetheless committed a crime and stolen something of value. The same applies to LLMs (well, just to let you know, there’s all manner of arcane debates on that -- I’ve covered those IP issues elsewhere, see the link here).

Jailbreaking Often Included

I’ve mentioned earlier that to do the AI distillation, you can merely enter everyday prompts. That is indeed the case. But sometimes there are special inner elements of AI that are guarded by the AI maker. For example, there are usually AI safeguards that won’t let you ask for details on how to make toxic poisons or explosive devices.

A foreign entity might want to get those facets from the AI.

To do so, they will employ various AI cracking schemes, often referred to as jailbreaking. The use of jailbreaking can potentially enable the foreign entity to extract secrets that are highly sensitive or supposed to be kept away from all users of the AI. For my discussion of how jailbreaking is undertaken, see the link here.

AI Distillation By Foreign Entities

Now that you are sufficiently up-to-speed about AI distillation, let’s shift our focus to how American makers of AI are being ripped off by foreign entities via the use of AI distillation techniques.

A publicly posted policy memorandum on April 23, 2026, by Michael J. Kratsios, Assistant to the President for Science and Technology Director in the White House Office of Science and Technology Policy, entitled “Adversarial Distillation of American AI Models,” made these salient points (excerpts):

  • “The United States leads the world in artificial intelligence (AI) technologies. That lead reflects decades of foundational research, bold entrepreneurial risk-taking, and hundreds of billions of dollars in annual private investment.”
  • “However, the United States government has information indicating that foreign entities, principally based in China, are engaged in deliberate, industrial-scale campaigns to distill U.S. frontier systems.”
  • “Leveraging tens of thousands of proxy accounts to evade detection and using jailbreaking techniques to expose proprietary information, these coordinated campaigns systematically extract capabilities from American AI models, exploiting American expertise and innovation.”
  • “Industrial distillation activities that aim to systematically undermine American research and development and access proprietary information are unacceptable.”

I liken these foreign entity activities to the types of subterfuge that took place during the Cold War era. I’m sure you know that spies would try to obtain American secrets, such as how to make certain kinds of missiles or weapons. Espionage tactics often leaned into the use of dispersed human actors, including individual researchers, governmental officials, industry practitioners, and others, to make copies of secret plans, proprietary documents, and so on.

The Big Picture Comes To Mind

Nowadays, those same spying tradecraft precepts are being retooled as AI bots that converge in proxy swarms on a targeted LLM in an AI distillation attack. This allows scaling far beyond what human hands alone could accomplish. Deploying thousands of semi-autonomous accounts to perform coordinated queries is relatively cheap and easy to undertake. It is much less expensive than building the same content from scratch, can be done in a fraction of the time in comparison to the right way to do things, and is quite difficult to detect.

Not the perfect crime, but it ranks up there in the AI underhanded cyberhacking world.

American companies working individually won’t necessarily have the wherewithal to tackle the spying tactics of AI distillation that occur on an industrial scale. Sure, they are doing what they can to devise AI safeguards around this, but the foreign entities are going after a wide swath of LLMs and can keep maneuvering as they do so.

A mix of defensive tactics and strategies is being constantly crafted and advanced.

Technical defenses include:

  • Behavioral monitoring across accounts (detect coordinated querying patterns).
  • Use of data watermarking or data fingerprinting to trace model lineage.
  • Adopt differential privacy or output perturbation (though this can degrade usefulness).
  • Enforce query throttling tied to aggregate signals, not just per-account limits.
  • Devise stronger jailbreak resistance via adversarial training.

Operational controls that can be implemented include:

  • Establish account verification tiers to limit high-volume access.
  • Enact API usage auditing and anomaly escalation.
  • Proceed with red-teaming focused on extraction scenarios.

Policy responses include:

  • Consider the adoption of various AI distillation-related export controls on model weights and high-end computing.
  • Craft legal frameworks treating large-scale AI extraction as IP theft and economic espionage.
  • Seek to establish agreed and enforceable international norms around AI model distillation practices.

Steps Outlined In The Memorandum

The recently released White House memorandum offers several steps that are being undertaken, including sharing information across American AI companies about AI distillation subterfuge taking place, and having the federal government work closely with AI makers to develop best practices for identifying, mitigating, and remediating these industrial-scale efforts by foreign entities.

It is a never-ending cat-and-mouse game.

There is a famous line known amongst AI insiders that there are two types of AI companies: those that have had their AI breached and those that don’t know it yet. Boom, drop the mic. Seriously, there are undoubtedly foreign entities at this very moment performing AI distillation on American-made LLMs. It is real. It is happening. And more is coming down the pike.

We must be vigilant, take proactive AI cybersecurity precautions, and protect the revered goose that lays the golden eggs.